The vendor explicitly states that these products are not affected by this CVE.
- All currently supported Red Hat products
- Summary
- A flaw was found in nnn. An attacker can exploit this vulnerability by placing a file with a specially crafted name, containing shell syntax, on a shared filesystem, removable media, or within an extracted archive. If a victim then navigates to and opens this file using the `preview-tabbed` feature, the malicious filename is embedded into a generated shell command. This allows the attacker's injected payload to execute with the privileges of the nnn process, leading to arbitrary code execution.
- Remediation
- No remediation text is recorded.
